Re: Advice on setting up a shell server

Stefan 'Kaishakunin' Schumacher <[email protected]>
Newsgroups gmane.os.netbsd.help
Message-ID <[email protected]>
Also sprach Martijn van Buul ([email protected])
> * Stefan 'Kaishakunin' Schumacher:
> > Use Systrace to systrace the login shell and restrict any access to
> > evil[tm] binaries, such as ftp/telnet.
> 
> pray tell, what's evil[tm] about ftp/telnet? Are you going to restrict
> browsers or things like wget/fetch too?
> 
> I'm not talking about ftpd or telnetd, but I *REALLY* don't see what's the
> evilness of someone acessing a ftp site somewhere, or accessing one of the
> few remaining telnet services

It depends on your local security policy what is declared evil and
what not. Things you might find OK are forbidden on other sites. So
what?

> > You can also use systrace to forbid the use of binaries in the home dirs of
> > students or to restrict=20 eg. SSH to your private network.
> 
> Why don't you also change the shell to /bin/nologin and pull the network plug?
> :)
> 
> Security is one thing. Turning the whole project pointless, all for the 
> benefit of security is another. At least, I'm sure that the intention of
> this project is to give students a usuable account, and not to give them
> something they cannot sensibly use or access.

First "usuable account" has to be defined, than one can create a
security policy for it. Or discuss single arrangements.
Like I said above, security is site-dependent and what I gave as
_example_ is useful on my servers. YMMV. 

-- 
Pedites pugnas decernent    http://www.jaegerseiten.de    Horrido!


http://www.net-tex.de                                 http://www.cryptomancer.de
signature.asc (application/pgp-signature, 186 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (NetBSD)

iD8DBQFFxJQPEfTEHrP7rjMRAmMHAJ9Rv8PxmJSnJFtw3WDCSXkILI4F2QCgq2eO
qa5W8mcURr/i06RhfJ2oij4=
=gnle
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.